Sceawere
Vulnerability Detail
CVE-2026-63045UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Apache mod_proxy_ftp SSRF Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.5
- Creation Date
- 1d ago
- Vendor
- Apache Software Foundation
- Product
- Apache HTTP Server
- Attack Type
- CWE-284 Improper Access Control
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
Improper validation of FTP PASV reply address in mod_proxy_ftp in Apache Software Foundation Apache HTTP Server through 2.4.68 on all platforms allows, in forward proxy configurations, an untrusted FTP server to cause the proxy to open a data connection to an arbitrary third-party host via a crafted PASV response. Users are recommended to upgrade to version 2.4.69, which fixes this issue.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.5",
"pubDate": "2026-10-01T17:17:29.680Z",
"pubdate": "2026-10-01T17:17:29.680Z",
"executiveSummary": "A vulnerability exists in the mod_proxy_ftp module of the Apache HTTP Server, affecting versions up to 2.4.68. This flaw is classified as a Server-Side Request Forgery (SSRF) vulnerability occurring within forward proxy configurations.\nThe issue arises from the improper validation of the IP address provided in the PASV (Passive Mode) reply from an FTP server. By providing a malicious PASV response, an attacker operating a rogue FTP server can induce the proxy to initiate unauthorized outbound connections to arbitrary third-party hosts on the network.\nThis vulnerability poses a significant risk to internal network security, as the proxy server can be coerced into scanning internal infrastructure, interacting with restricted services, or participating in blind exploitation attempts against otherwise unreachable targets. Successful exploitation does not require prior authentication to the proxy, as the attacker leverages the server's role as a legitimate intermediary during a client-requested FTP session. Organizations are urged to upgrade to Apache HTTP Server 2.4.69 to mitigate this risk.",
"technicalDetails": "The root cause of this vulnerability lies in the insufficient input validation of the address information contained within the PASV command response handled by the mod_proxy_ftp module. In the FTP protocol, when a client (in this case, the Apache proxy) requests a passive data connection, the FTP server replies with the PASV response, which includes the IP address and port that the client should connect to for the data transfer.\nThe vulnerability allows an untrusted FTP server to send a crafted PASV response containing an arbitrary IP address or hostname instead of the address belonging to the FTP server itself. Because mod_proxy_ftp fails to verify that the returned IP address matches the IP address of the FTP server currently being proxied, the Apache process consumes this input directly to establish a backend data connection.\nThe attack flow proceeds as follows: 1) A user or attacker directs the Apache forward proxy to establish a connection to a malicious FTP server. 2) The Apache proxy negotiates the connection and issues a PASV command. 3) The malicious FTP server responds with a PASV reply containing a targeted internal or external IP address and a specific TCP port. 4) The mod_proxy_ftp module blindly attempts to open a TCP socket to the address specified in the PASV response. 5) The proxy acts as a bridge, successfully initiating a connection to the victim third-party host on behalf of the attacker.\nThis behavior results in a Server-Side Request Forgery (SSRF) condition. An attacker can use this to bypass network segmentation, probe for open ports on internal hosts that are not exposed to the public internet, or interact with administrative interfaces accessible only from the proxy's network segment. The proxy essentially becomes a pivot point for the attacker. Because the connection is initiated by the Apache HTTP Server process, the source IP of the request appears to be the proxy itself, potentially bypassing IP-based access control lists (ACLs) or perimeter firewalls that trust the proxy server.\nThe vulnerability is restricted to environments utilizing mod_proxy_ftp in a forward proxy configuration. It affects all Apache HTTP Server versions through 2.4.68 on all supported platforms. No user interaction or authentication is required for the attacker-controlled FTP server to trigger this behavior, provided the attacker can successfully lure or direct the proxy to interact with their malicious service."
}